CVE-2020-25108: Critical severity ethernut nut/os vulnerability
An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The DNS response data length is not checked (it can be set to an arbitrary value from a packet). This may lead to successful Denial-of-Service, and possibly Remote Code Execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25108?
CVE-2020-25108 has a high severity level due to the potential for Denial-of-Service and possibly Remote Code Execution.
How do I fix CVE-2020-25108?
To fix CVE-2020-25108, update your software to versions that have addressed the DNS response data length validation issue.
What software is affected by CVE-2020-25108?
CVE-2020-25108 affects several software products, including Nut/OS 5.1, uIP-Contiki-OS, uIP-Contiki-NG, and open-iscsi 2.1.12 and prior.
What kind of attack can occur due to CVE-2020-25108?
Due to CVE-2020-25108, an attacker can exploit the vulnerability to potentially execute a Denial-of-Service attack or Remote Code Execution.
Is CVE-2020-25108 easy to exploit?
Yes, the lack of DNS response data length checks in CVE-2020-25108 can make it easier for attackers to exploit the vulnerability.